SlideShare ist ein Scribd-Unternehmen logo
1 von 19
Informaciona bezbednost u Srbiji i
      open source rešenja




                           Nikola Milošević
                     nikola.milosevic@owasp.org
About Me



•   OWASP Serbia local chapter leader
•   OWASP anti-malware project contributor
•   OWASP LC Srbija postoji od februara 2012
•   Jednom mesecno predavanja na ETF
•   Mailing lista
•   https://www.owasp.org/index.php/Serbia
Informaciona bezbednost u
                                       Srbiji


•   Ne obraća se pažnja na bezbednost
•   Porast napada u poslednjih nekoliko godina
•   Napadačke tehnike su u razvoju
•   Ranjivi veliki sistemi (državne institucije, banke)
Informaciona bezbednost u
          Srbiji
Informaciona bezbednost u
                                Srbiji


• Povećana kompeksnost malvera i napadačkih
  alata
• Radoznalost
• Cyber kriminal
• Hacktivizam
• Tehnološka špijunaža
• Cyber rat
Kako se zaštiti?



• Kako se zaštiti?

•   Bezbedan kod
•   Testiranje i retestiranje
•   Be up to date (osvežavati znanje)
•   Update softvera i korišćenih biblioteka
•   Edukacija korisnika
OWASP Projekti



• 3 grupe OWASP projekata:
  – Protect – Alati i dokumenti koji imaju ulogu da štite
  – Detect – Alati i dokumenti koji imaju ulogu da nađu
  – Life Cycle – Alati i dokumenti koji se koriste da bi
    dodali bezbednosne mehanizme u Software
    Development Lifecycle
Guides and documents



• OWASP Top 10
• OWASP Application Security Verification
  Standard
• OWASP Code Review Guide
• OWASP Testing Guide
OWASP Frameworks


• OWASP AntySami Project (Java,.NET)
   – API za validiranje bogatih HTML/CSS unosa korisnika bez
     izloženosti cross-site scripting i phishing napadima
• OWASP Enterprise Security API (ESAPI)
   – Slobodna i otvorena kolekcija svih bezbednostih metoda
     za kojima developer ima potrebu da bi napravio sigurnu
     web aplikaciju
• OWASP Mod Security Rule Set Project
   – web application firewall engine
   – Generička zaštita od ranjivosti koje se često nalaze u web
     aplikacijama
OWASP alati


• OWASP Code Crawler (beta)
   – Statički alat za code review. Traži bezbednostne propuste
     u .NET i J2EE (java)
• OWASP Web Scarab Project
   – Alat za vršenje bezbednostih testova na web aplikacijama
• OWASP Zed Attack Proxy
   – penetration testing alat za nalaženje ranjivostu u web
     aplikacijama
   – Koriste ga ljudi sa različitim iskustvom
   – Toolsmith tool of the year 2011
Kozice



• Edukacioni projekat
• Želite li da naučite kako se testira bezbednost
  web aplikacija?
• Probajte Web Goat!
• Naučite da izvedete OWASP Top 10
• Drugi koziji projekti:
  – GoatDroid
  – iGoat
Non OWASP



•   Nmap
•   Sqlmap
•   WireShark
•   Snort

• ODESSA (Open Digital Evidence Search and
  Seizure Architecture)
• ...
Don’t get hacked
Protect yourself
Pitanja i diskusija




nikola.milosevic@owasp.org

Weitere ähnliche Inhalte

Ähnlich wie Software Freedom day Serbia - Owasp open source resenja

Ähnlich wie Software Freedom day Serbia - Owasp open source resenja (7)

IT1 1.3 Internet pod haubom
IT1 1.3 Internet pod haubomIT1 1.3 Internet pod haubom
IT1 1.3 Internet pod haubom
 
Java
JavaJava
Java
 
Arhimedes2015-VelimirRadlovacki
Arhimedes2015-VelimirRadlovackiArhimedes2015-VelimirRadlovacki
Arhimedes2015-VelimirRadlovacki
 
Decouple Goals
Decouple GoalsDecouple Goals
Decouple Goals
 
Hadoop i sveprisutno racunarstvo
Hadoop i sveprisutno racunarstvoHadoop i sveprisutno racunarstvo
Hadoop i sveprisutno racunarstvo
 
Hadoop i sveprisutno računarstvo
Hadoop i sveprisutno računarstvoHadoop i sveprisutno računarstvo
Hadoop i sveprisutno računarstvo
 
Programiranje Nadja Arsenijevic
Programiranje Nadja ArsenijevicProgramiranje Nadja Arsenijevic
Programiranje Nadja Arsenijevic
 

Mehr von Nikola Milosevic

Classifying intangible social innovation concepts using machine learning and ...
Classifying intangible social innovation concepts using machine learning and ...Classifying intangible social innovation concepts using machine learning and ...
Classifying intangible social innovation concepts using machine learning and ...Nikola Milosevic
 
Machine learning (ML) and natural language processing (NLP)
Machine learning (ML) and natural language processing (NLP)Machine learning (ML) and natural language processing (NLP)
Machine learning (ML) and natural language processing (NLP)Nikola Milosevic
 
AI an the future of society
AI an the future of societyAI an the future of society
AI an the future of societyNikola Milosevic
 
Machine learning prediction of stock markets
Machine learning prediction of stock marketsMachine learning prediction of stock markets
Machine learning prediction of stock marketsNikola Milosevic
 
Equity forecast: Predicting long term stock market prices using machine learning
Equity forecast: Predicting long term stock market prices using machine learningEquity forecast: Predicting long term stock market prices using machine learning
Equity forecast: Predicting long term stock market prices using machine learningNikola Milosevic
 
BelBi2016 presentation: Hybrid methodology for information extraction from ta...
BelBi2016 presentation: Hybrid methodology for information extraction from ta...BelBi2016 presentation: Hybrid methodology for information extraction from ta...
BelBi2016 presentation: Hybrid methodology for information extraction from ta...Nikola Milosevic
 
Extracting patient data from tables in clinical literature
Extracting patient data from tables in clinical literatureExtracting patient data from tables in clinical literature
Extracting patient data from tables in clinical literatureNikola Milosevic
 
Supporting clinical trial data curation and integration with table mining
Supporting clinical trial data curation and integration with table miningSupporting clinical trial data curation and integration with table mining
Supporting clinical trial data curation and integration with table miningNikola Milosevic
 
Mobile security, OWASP Mobile Top 10, OWASP Seraphimdroid
Mobile security, OWASP Mobile Top 10, OWASP SeraphimdroidMobile security, OWASP Mobile Top 10, OWASP Seraphimdroid
Mobile security, OWASP Mobile Top 10, OWASP SeraphimdroidNikola Milosevic
 
Sentiment analysis for Serbian language
Sentiment analysis for Serbian languageSentiment analysis for Serbian language
Sentiment analysis for Serbian languageNikola Milosevic
 
Mašinska analiza sentimenta rečenica na srpskom jeziku
Mašinska analiza sentimenta rečenica na srpskom jezikuMašinska analiza sentimenta rečenica na srpskom jeziku
Mašinska analiza sentimenta rečenica na srpskom jezikuNikola Milosevic
 
OWASP Serbia - A6 security misconfiguration
OWASP Serbia - A6 security misconfigurationOWASP Serbia - A6 security misconfiguration
OWASP Serbia - A6 security misconfigurationNikola Milosevic
 
OWASP Serbia - A5 cross-site request forgery
OWASP Serbia - A5 cross-site request forgeryOWASP Serbia - A5 cross-site request forgery
OWASP Serbia - A5 cross-site request forgeryNikola Milosevic
 
OWASP Serbia - A3 broken authentication and session management
OWASP Serbia - A3 broken authentication and session managementOWASP Serbia - A3 broken authentication and session management
OWASP Serbia - A3 broken authentication and session managementNikola Milosevic
 

Mehr von Nikola Milosevic (20)

Classifying intangible social innovation concepts using machine learning and ...
Classifying intangible social innovation concepts using machine learning and ...Classifying intangible social innovation concepts using machine learning and ...
Classifying intangible social innovation concepts using machine learning and ...
 
Machine learning (ML) and natural language processing (NLP)
Machine learning (ML) and natural language processing (NLP)Machine learning (ML) and natural language processing (NLP)
Machine learning (ML) and natural language processing (NLP)
 
Veštačka inteligencija
Veštačka inteligencijaVeštačka inteligencija
Veštačka inteligencija
 
AI an the future of society
AI an the future of societyAI an the future of society
AI an the future of society
 
Machine learning prediction of stock markets
Machine learning prediction of stock marketsMachine learning prediction of stock markets
Machine learning prediction of stock markets
 
Equity forecast: Predicting long term stock market prices using machine learning
Equity forecast: Predicting long term stock market prices using machine learningEquity forecast: Predicting long term stock market prices using machine learning
Equity forecast: Predicting long term stock market prices using machine learning
 
BelBi2016 presentation: Hybrid methodology for information extraction from ta...
BelBi2016 presentation: Hybrid methodology for information extraction from ta...BelBi2016 presentation: Hybrid methodology for information extraction from ta...
BelBi2016 presentation: Hybrid methodology for information extraction from ta...
 
Extracting patient data from tables in clinical literature
Extracting patient data from tables in clinical literatureExtracting patient data from tables in clinical literature
Extracting patient data from tables in clinical literature
 
Supporting clinical trial data curation and integration with table mining
Supporting clinical trial data curation and integration with table miningSupporting clinical trial data curation and integration with table mining
Supporting clinical trial data curation and integration with table mining
 
Mobile security, OWASP Mobile Top 10, OWASP Seraphimdroid
Mobile security, OWASP Mobile Top 10, OWASP SeraphimdroidMobile security, OWASP Mobile Top 10, OWASP Seraphimdroid
Mobile security, OWASP Mobile Top 10, OWASP Seraphimdroid
 
Serbia2
Serbia2Serbia2
Serbia2
 
Malware
MalwareMalware
Malware
 
Sentiment analysis for Serbian language
Sentiment analysis for Serbian languageSentiment analysis for Serbian language
Sentiment analysis for Serbian language
 
Http and security
Http and securityHttp and security
Http and security
 
Android business models
Android business modelsAndroid business models
Android business models
 
Mašinska analiza sentimenta rečenica na srpskom jeziku
Mašinska analiza sentimenta rečenica na srpskom jezikuMašinska analiza sentimenta rečenica na srpskom jeziku
Mašinska analiza sentimenta rečenica na srpskom jeziku
 
OWASP Serbia - A6 security misconfiguration
OWASP Serbia - A6 security misconfigurationOWASP Serbia - A6 security misconfiguration
OWASP Serbia - A6 security misconfiguration
 
OWASP Serbia - A5 cross-site request forgery
OWASP Serbia - A5 cross-site request forgeryOWASP Serbia - A5 cross-site request forgery
OWASP Serbia - A5 cross-site request forgery
 
OWASP Serbia - A3 broken authentication and session management
OWASP Serbia - A3 broken authentication and session managementOWASP Serbia - A3 broken authentication and session management
OWASP Serbia - A3 broken authentication and session management
 
Owasp Serbia: sqli,xss
Owasp Serbia: sqli,xssOwasp Serbia: sqli,xss
Owasp Serbia: sqli,xss
 

Software Freedom day Serbia - Owasp open source resenja

  • 1. Informaciona bezbednost u Srbiji i open source rešenja Nikola Milošević nikola.milosevic@owasp.org
  • 2. About Me • OWASP Serbia local chapter leader • OWASP anti-malware project contributor • OWASP LC Srbija postoji od februara 2012 • Jednom mesecno predavanja na ETF • Mailing lista • https://www.owasp.org/index.php/Serbia
  • 3. Informaciona bezbednost u Srbiji • Ne obraća se pažnja na bezbednost • Porast napada u poslednjih nekoliko godina • Napadačke tehnike su u razvoju • Ranjivi veliki sistemi (državne institucije, banke)
  • 5.
  • 6.
  • 7.
  • 8.
  • 9. Informaciona bezbednost u Srbiji • Povećana kompeksnost malvera i napadačkih alata • Radoznalost • Cyber kriminal • Hacktivizam • Tehnološka špijunaža • Cyber rat
  • 10. Kako se zaštiti? • Kako se zaštiti? • Bezbedan kod • Testiranje i retestiranje • Be up to date (osvežavati znanje) • Update softvera i korišćenih biblioteka • Edukacija korisnika
  • 11. OWASP Projekti • 3 grupe OWASP projekata: – Protect – Alati i dokumenti koji imaju ulogu da štite – Detect – Alati i dokumenti koji imaju ulogu da nađu – Life Cycle – Alati i dokumenti koji se koriste da bi dodali bezbednosne mehanizme u Software Development Lifecycle
  • 12. Guides and documents • OWASP Top 10 • OWASP Application Security Verification Standard • OWASP Code Review Guide • OWASP Testing Guide
  • 13. OWASP Frameworks • OWASP AntySami Project (Java,.NET) – API za validiranje bogatih HTML/CSS unosa korisnika bez izloženosti cross-site scripting i phishing napadima • OWASP Enterprise Security API (ESAPI) – Slobodna i otvorena kolekcija svih bezbednostih metoda za kojima developer ima potrebu da bi napravio sigurnu web aplikaciju • OWASP Mod Security Rule Set Project – web application firewall engine – Generička zaštita od ranjivosti koje se često nalaze u web aplikacijama
  • 14. OWASP alati • OWASP Code Crawler (beta) – Statički alat za code review. Traži bezbednostne propuste u .NET i J2EE (java) • OWASP Web Scarab Project – Alat za vršenje bezbednostih testova na web aplikacijama • OWASP Zed Attack Proxy – penetration testing alat za nalaženje ranjivostu u web aplikacijama – Koriste ga ljudi sa različitim iskustvom – Toolsmith tool of the year 2011
  • 15. Kozice • Edukacioni projekat • Želite li da naučite kako se testira bezbednost web aplikacija? • Probajte Web Goat! • Naučite da izvedete OWASP Top 10 • Drugi koziji projekti: – GoatDroid – iGoat
  • 16. Non OWASP • Nmap • Sqlmap • WireShark • Snort • ODESSA (Open Digital Evidence Search and Seizure Architecture) • ...